Digilac

Legal

Privacy policy

This page explains what happens to personal data on digilac.ch — what we collect, who else sees it, where it goes, and what you can ask us to do about it.

Who is responsible

The controller for the processing described here is:
Digilac Sàrl, Espace de l’Europe 2, 2000 Neuchâtel, Switzerland
info@digilac.ch+41 79 327 42 45

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP, SR 235.1) and its ordinance (DPO, SR 235.11). Where the EU General Data Protection Regulation applies to a particular visitor, we apply it in addition. Full company details are in our legal notice.

When you browse this site

Our hosting provider, Vercel Inc., processes technical data on our behalf so the site can be delivered and protected: your IP address, the pages requested, timestamps, your browser and operating system. These server logs are kept for a short period for security and troubleshooting, and are not used to build a profile of you. This happens for every visitor — it is what makes serving the page possible at all.

When you write to us

The contact form collects the name, company, email address, topic, and message you type. Two things happen with it:

  • Spam protection. Before the message is accepted, Cloudflare Turnstile checks that you are not a bot. Cloudflare, Inc. receives your IP address and technical signals about your browser for that check. We cannot switch this off without leaving the form open to abuse, so it runs on every submission.
  • Delivery. Your message is then posted into our internal Google Chat workspace, where our team reads and answers it. Google therefore processes the content of your message as our provider of workplace systems.

If that delivery fails, a copy of your message is kept in our analytics system so that a technical failure on our side does not silently discard what you wrote, and so we can still answer you. This only ever happens when the message did not get through.

We keep contact messages as long as needed to handle your request and any follow-up, and afterwards only where accounting or legal retention obligations require it.

When you book a call

Scheduling runs on Google Calendar appointment scheduling, shown in a window on our contact page. Nothing is loaded from Google until you open that window, and whatever you enter there is handled by Google under its own terms in addition to ours.

When you open the map

The map on our about page is served by Google Maps. It stays unloaded behind a button: Google receives nothing — no IP address, no cookies — unless you choose to display it.

Analytics and cookies

With your consent, we use PostHog to measure how this site is used, so we can improve it. It sets cookies and records the pages you view, how you interact with them, and a replay of your navigation in which everything you type is masked. If you send us the contact form, your email address is linked to that data, and the outcome of that submission is recorded alongside it.

Nothing is loaded before you accept, and you can withdraw at any time via Cookie settings at the bottom of any page. Withdrawing stops the collection and detaches this browser from what was collected before. The data is processed on our behalf by PostHog Inc. and stored in the European Union; your IP address is not stored.

Session recordings are deleted automatically after 30 days. The measurement data behind them is kept only as long as it remains useful to improve the site, and we delete what no longer serves that purpose.

What we don't do

We do not sell personal data, we do not set advertising or cross-site tracking cookies, and we take no automated decisions with legal or similarly significant effects about you.

Where your data goes

The providers above act as our processors. Some of them are based outside Switzerland:

  • Vercel Inc. — hosting, United States
  • Cloudflare, Inc. — spam protection on the contact form, United States
  • Google — message delivery, call booking, and maps; European Union and United States
  • PostHog Inc. — analytics and undelivered contact messages, United States, with the data stored in the European Union

Where a recipient is certified under the Swiss–U.S. Data Privacy Framework, the Federal Council's adequacy decision covers the transfer. Otherwise we rely on the standard contractual clauses recognised by the Federal Data Protection and Information Commissioner (Art. 16 para. 2 let. d FADP).

Keeping it safe

We take appropriate technical and organisational measures to protect personal data against loss and unauthorised access, as required by Art. 8 FADP. No transmission over the internet can be guaranteed to be completely secure, which is why the contact form asks for no more than we need to answer you — please don't send us sensitive information through it.

Your rights

You may at any time ask us for access to the personal data we hold about you, and for its correction, deletion, or the handing over of the data you gave us — including your measurement data and any session recording. Write to info@digilac.ch and we will answer within 30 days. We may ask you to identify yourself first, so that we don't hand your data to someone else.

If you believe we are handling your data wrongly, you can contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern — edoeb.admin.ch. If the GDPR applies to you, you may instead complain to the supervisory authority where you live.

Changes

We update this policy when what we do with data changes. The current version is always the one on this page.

Last updated: 20 August 2026